Public agent API / v1

Authentication

REST and MCP accept the same Clerk OAuth 2.1 access tokens. QuiltLab does not issue API keys in v1.

Discover and authorize

  1. Read llms.txt or the API catalog to find the published surface.
  2. Fetch protected-resource metadata. Follow the returned authorization server to its OAuth authorization-server metadata.
  3. Use your OAuth client to complete authorization with Clerk and exchange the authorization code at the discovered token_endpoint. Use the discovered resource identifier for the connection.
  4. Send the resulting access token as a bearer token on REST requests or let your MCP client manage the connection.

QuiltLab's authorization-server metadata proxy is GET-only. It is not a token endpoint. Read endpoint URLs from discovery rather than constructing them.

Authorization: Bearer <access_token>

Probe GET /api/v1/auth/me before calling private design operations. It returns success: true and data containing authenticated and the caller's userId; it does not return email or collaborator identities.

Public and private operations

Fabric catalog searches and supply guides allow anonymous reads. Your projects and saved designs require authentication. A supplied invalid or expired bearer token returns HTTP 401, even if a valid browser session is present.

A 401 includes WWW-Authenticate with a resource_metadata URL. Follow it to reauthorize; see Errors for the response shape.

Browser sessions and request origins

Same-origin browser clients can use their Clerk session cookie instead of a bearer token. Cookie-authenticated writes run the CSRF origin check: supplied Origin and Referer origins must be allowed. This API does not require a separate CSRF-token header.

GET and HEAD requests do not run the write check. OAuth bearer writes skip this cookie-specific check. Use OAuth for external integrations; do not copy browser cookies into agents.